If a PKCS#12 file contains a server certificate that is signed by an intermediate CA rather than by a root CA, you must import the PKCS#12 keystore into a JKS keystore. See Convert a PKCS#12 File to JKS Format.